CVE-2026-87450

Google · Chrome

Incorrect authorization in Google Chrome permissions allows a remote attacker to obtain sensitive information via a crafted extension.

Executive summary

A vulnerability in Google Chrome allows remote attackers to bypass authorization controls and access sensitive information through malicious browser extensions.

Vulnerability

This vulnerability involves incorrect authorization within the browser permissions model, which can be exploited by an attacker using social engineering to facilitate unauthorized data access. The flaw is exploitable by an unauthenticated remote attacker.

Business impact

The ability for an unauthorized party to access sensitive user information poses a significant risk to data privacy and organizational security. While the CVSS score of 7.5 indicates a high severity, the potential for data exfiltration via browser extensions could lead to the compromise of corporate credentials or proprietary information.

Remediation

Immediate Action: Update all instances of Google Chrome to version 153.0.8010.36 or later immediately to apply the necessary authorization fixes.

Proactive Monitoring: Monitor browser extension installation logs and endpoint security telemetry for unauthorized or suspicious extension activity across the fleet.

Compensating Controls: Implement browser management policies that restrict the installation of extensions to only those explicitly approved or managed by the organization.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the high CVSS score and the nature of the flaw, administrators should treat this update with high priority. Organizations should enforce browser version compliance through centralized management tools to ensure all endpoints are patched against this authorization bypass.

More Google CVEs all →

History

CVE Brief tracked this CVE 3 days before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 7.5 (3.1)
  4. Analyst report written

Sources